PCI Assurance Analyst

Selfridges

Greater London

On-site

GBP 65,000 - 90,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Selfridges is seeking a PCI Assurance Analyst to act as our PCI DSS SME and lead for compliance across people, processes and technology. You will assess, evidence, and remediate PCI DSS controls while coordinating SAQs, AOC, and external audits with IT, security, and business teams.

The role reports to the IT Security and GRC Manager and can be based in London or Leicester, enabling close collaboration with stakeholders to reduce regulatory, financial, and reputational risk related to payment

Qualifications

  • Experience as a PCI DSS/IT security governance professional.
  • Strong understanding of PCI DSS scope, validation, and evidence expectations.
  • Ability to coordinate SAQs, AOC, and external audits across IT and business teams.

Responsibilities

  • Interpret PCI DSS requirements for the card environment across people, process, and technology.
  • Perform gap assessments and identify non‑compliance or control weaknesses.
  • Coordinate PCI compliance activities including SAQs, AOC, and annual validations; review evidence.
  • Liaise with QSAs, acquirers, and payment brands during audits.
  • Track remediation plans and maintain PCI documentation and risk assessments.
  • Provide assurance reporting to senior management on status, risks, and audit readiness.

Skills

PCI DSS
IT security governance
Gap analyses
Evidence review
Stakeholder communication
Audits coordination

Education

Bachelor's degree
ISO 27001 foundation/lead implementer/lead auditor
PCI Professional (PCIP)

Job description

PCI Assurance Analyst
Job Introduction
What is the role?

Reporting to the IT Security and IT GRC Manager, the PCI Assurance Analyst acts as our Payment Card Industry Data Security Standard (PCI DSS) subject matter expert and lead for the PCI-DSS compliance process.

Our PCI Assurance Analyst is responsible for ensuring compliance with the PCI DSS by assessing, validating, and evidencing how cardholder data is protected across people, processes and technology.

The role involves interpreting PCI requirements, conducting control assessments and gap analyses, coordinating self‑assessments or external audits, reviewing technical and procedural evidence and working closely with IT, security, and business teams to remediate compliance gaps. Our PCI Assurance Analyst also maintains compliance documentation, tracks remediation plans, supports Qualified Security Assessor (QSA) engagements, and provides clear assurance reporting to stakeholders, helping reduce regulatory, financial, and reputational risk associated with payment card data.

The role can be based in either London or Leicester.

Role responsibilities
  • Interpret and apply PCI DSS requirements to our payment card environment across people, process, and technology
  • Perform PCI DSS gap assessments against current controls and identify areas of non‑compliance or control weakness
  • Coordinate and manage PCI compliance activities including Self‑Assessment Questionnaires (SAQs), Attestations of Compliance (AOC), and annual validation cycles. Collect, review and validate evidence
  • Act as the primary liaison with Qualified Security Assessors (QSAs), acquirers, and payment brands during audits and assessments
  • Track and support remediation plans, ensuring issues are clearly documented, risk‑assessed, prioritised, and resolved
  • Maintain accurate PCI documentation, including scoping diagrams, risk assessments, policies, and procedures
  • Support PCI scoping decisions, ensuring only necessary systems are in scope and controls are applied appropriately
  • Provide assurance reporting to senior management on compliance status, risks, exceptions, and audit readiness
  • Advise delivery teams on secure design and change impacts related to PCI‑scoped systems
  • Monitor changes to the PCI DSS standard and assess their impact on existing controls and future compliance obligations
  • Promote a strong compliance and security culture through guidance, education, and pragmatic risk‑based advice
Skills & Experience:
  • Experience as an Information Security Governance Analyst is necessary for this role.
  • Strong working knowledge of PCI DSS (scoping, requirements, validation methods, evidence expectations)
  • Ability to interpret control intent and apply it pragmatically in real environments
  • Understanding of risk‑based assurance and control effectiveness
  • General understanding of IT infrastructure, cloud services, networks, and application architecture
  • Familiarity with payment environments, including POS, ecommerce platforms, payment gateways, tokenisation, and third‑party service providers
  • Ability to read and critique technical evidence (e.g. firewall rules, vulnerability scans, access logs)
  • Experience performing gap analyses, control testing, and evidence reviews
  • Strong attention to detail with the ability to spot control weaknesses or inconsistencies
  • Ability to work effectively with IT, Security, POS, Infrastructure, DevOps, and suppliers
  • Confident communicator who can explain compliance requirements to non‑specialists
  • Capable of producing clear assurance reporting for senior stakeholders
  • Experience working in PCI DSS compliance, IT security assurance, audit, GRC, or risk management
  • PCI Professional (PCIP) (highly desirable)
  • ISO 27001 foundation / lead implementer / lead auditor
  • CISM, CISSP, CRISC, or similar (beneficial, not always required)

Selfridges

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

PCI Assurance Analyst
PCI Assurance Analyst

Selfridges • City Of London

On-site
GBP 60,000 - 90,000
PCI DSS Assurance Specialist
PCI DSS Assurance Specialist

Selfridges • Greater London

On-site
GBP 65,000 - 90,000
PCI DSS Compliance & Assurance Analyst
PCI DSS Compliance & Assurance Analyst

Selfridges • City Of London

On-site
GBP 60,000 - 90,000
IT Security & PCI Compliance Manager
IT Security & PCI Compliance Manager

Marshall Wolfe • Luton

Hybrid
GBP 75,000 - 90,000
InfoSec Analyst II (GRC) Information security London
InfoSec Analyst II (GRC) Information security London

Checkout Ltd • Greater London

Hybrid
GBP 50,000 - 70,000
Snacks and meals provided
Collaborative work environment
Security Assurance Analyst
Security Assurance Analyst

Caraffi • Reading

Hybrid
GBP 60,000 - 85,000
Information Security Analyst
Information Security Analyst

allpay Limited • Hereford

On-site
GBP 35,000 - 52,000
Defined contribution pension
Income protection
Life assurance
+6
Information Security Analyst II (GRC)
Information Security Analyst II (GRC)

Checkout.com • Greater London

Hybrid
GBP 60,000 - 80,000
Snack and lunch options
Flexible working model
Assistant Manager – Information Security
Assistant Manager – Information Security

Jobtailor • Greater London

Hybrid
GBP 70,000 - 95,000
Security Compliance Manager - PCI DSS specialist
Security Compliance Manager - PCI DSS specialist

Virgin Media O2 • Birmingham

On-site
GBP 70,000 - 100,000